Executive brief
DSpace, an open-source platform for digital repositories, contains a vulnerability in its Curation Task feature. An attacker with administrative credentials can manipulate file output paths to overwrite critical system files or configuration settings. This could lead to a complete service outage or unauthorized changes to the platform's behavior.
Technical details
A path traversal vulnerability exists in the DSpace Curation Task Reporter due to insufficient validation of the output path parameter (-r). While originally a command-line tool, the feature is now accessible via the web UI to Collection, Community, and Site Administrators. An attacker with these administrative privileges can specify an arbitrary output path writable by the web server user (e.g., 'tomcat'). This can be used to overwrite configuration files in /dspace/config or binaries in /dspace/bin, potentially leading to Denial of Service (DoS) or further privilege escalation if combined with other vulnerabilities. The fix restricts output to configured directories and disables the reporter parameter for web-managed processes.
Affected products
- DSpace DSpace <= 7.6.6, 8.0 <= 8.3, 9.0 <= 9.2, 10-rc1
Timeline
- 2026-06-01: disclosed
- 2026-07-08: advisory: GitHub Advisory published
References
- https://api.github.com/users/superpegaso2703
- https://github.com/superpegaso2703
- https://api.github.com/users/superpegaso2703/gists%7B/gist_id%7D
- https://api.github.com/users/superpegaso2703/repos
- https://avatars.githubusercontent.com/u/177873564?v=4
- https://api.github.com/users/superpegaso2703/events%7B/privacy%7D